Security and reliability

Private by default. Explicit when shared.

Trellvia is designed around clear account boundaries, narrowly granted collaboration, server-authoritative access, and a durability contract that treats visible writing as work worth protecting.

Trellvia account settings with sign-in methods and authentication policy controls
01

Private work stays private

Account membership and administrative roles do not automatically grant access to another member's scratchpad, private documents, folders, or standalone tasks.

02

Authorization is checked on the server

Trellvia resolves the current session, identity, account, membership, role, and applicable grants instead of trusting browser-provided identity claims.

03

Sharing is explicit and reversible

Document and folder access uses named View or Edit permissions. Public links can be replaced, expired, paused, or revoked by the owner and constrained by account policy.

04

Accepted edits are recoverable

Editor changes are persisted to durable device storage first, synchronized continuously, and backed by previewable document versions.

Identity and sessions

Identity proves who you are. It does not decide which content you can open.

Trellvia uses provider-independent identity records and secure, HTTP-only application sessions. Google sign-in is verified on the server, and application access is still governed by the active account, membership, role, and asset permissions.

  • Opaque session credentials stored as cryptographic hashes on the server
  • Rotation after authentication and privilege changes
  • Review and revocation of other active browser sessions
  • Immediate invalidation after identity, membership, or policy changes

Team boundaries

Administration and content access remain separate.

Team owners and administrators can manage invitations, roles, account settings, and authentication policy. That authority does not silently provide access to a member's private workspace. Sharing grants remain the source of document and folder access.

  • Owner, Administrator, and Member roles
  • Separate personal and team workspace partitions
  • View and Edit grants for selected people or the account
  • Content-minimized audit events for administrative changes

Managed authentication

Stronger team policy requires verified readiness.

Team workspaces can prepare to require managed Google Workspace identities from DNS-verified domains. Enforcement is designed to remain unavailable until owner recovery, administrator identity, policy revision, and affected-session checks are satisfied.

  • DNS domain-control challenge before enforcement
  • Signed managed-domain claims instead of email-suffix checks
  • Owner Recovery Kit enrollment after fresh authentication
  • Immediate revocation of noncompliant sessions when enabled

Durability and recovery

Saving is continuous, and restoration is deliberate.

Every accepted editor transaction is written to the device before synchronization. Pending work uses stable operation identities so retries do not create duplicates. Historical versions open in a read-only preview before a separate confirmed restore.

  • Device-local recovery and durable synchronization queue
  • Automatic retry after focus, launch, and reconnection
  • Conflict handling that preserves the visible draft
  • Restore creates a new current version and keeps prior history

Plain-language commitment

Security claims should describe controls that exist—not badges that do not.

Trellvia's control design can support a future formal assurance program, but architecture and good intentions are not a certification. This page describes product boundaries and implemented control models without implying an audit or compliance status that has not been earned.

Keep the thread moving

A calm workspace begins with trust.

Keep private work private, share deliberately, and return to writing that is still there.

Open Trellvia